← Vulnerability feed

Vulnerability record · CVE-2025-13052 · published 12 December 2025

CVE-2025-13052: Asustor data master improper certificate validation vulnerability

AAsustor · Data Master

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the SMTP. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RKD2 as well as from ADM 5.0.0 through ADM 5.1.0.RN42.

7.0 CVSS 4.0 High EPSS 0.18% · top 93.3% CWE-295 · Improper certificate validation
7.0CVSS 4.0 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacker who can intercept network traffic between the SMTP client and server to execute a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the SMTP. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RKD2 as well as from ADM 5.0.0 through ADM 5.1.0.RN42.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-13052 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12313Asustor data master os command injection vulnerabilityOS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity…EPSS 4.4%9.5CVE-2026-24936Asustor data master improper input validation vulnerabilityWhen a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr…EPSS 0.81%9.4CVE-2026-6644Asustor data master os command injection vulnerabilityA command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r…EPSS 2.1%9.2CVE-2026-3179Asustor data master path traversal vulnerabilityThe FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MI…EPSS 0.77%8.9CVE-2026-24932Asustor data master improper certificate validation vulnerabilityThe DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS,…EPSS 0.21%8.9CVE-2026-24933Asustor data master improper certificate validation vulnerabilityThe API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validat…EPSS 0.21%8.8CVE-2023-2910Asustor data master command injection vulnerabilityImproper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Ma…EPSS 1.6%8.8CVE-2023-3697Asustor data master path traversal vulnerabilityPrinter service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and …EPSS 0.66%

Source: NIST National Vulnerability Database (record CVE-2025-13052), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.